ATLAS Landscape
AML.T0011.003

Malicious Link

An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client Execution. Links may also lead users to download files that require execution via Malicious File. There are many ways an adversary can leverage malicious links to gain access to a victim system via an AI system. For example, an AI Agent that is configured to not validate website origin headers will accept connections from any website, allowing adversaries the ability to get around previously inaccessible network.

Severity CVE CVSS
CRITICAL CVE-2026-33749 9.0
HIGH CVE-2021-39160 8.8
HIGH CVE-2026-25750 8.1
HIGH CVE-2024-7806 8.0
HIGH CVE-2025-64496 7.3
HIGH CVE-2026-44721 7.3
MEDIUM CVE-2024-7035 6.9
MEDIUM CVE-2024-7044 6.8
MEDIUM CVE-2024-6581 6.5
MEDIUM CVE-2026-26320 6.5
MEDIUM CVE-2024-37146 6.1
MEDIUM CVE-2025-25296 6.1
MEDIUM CVE-2021-28796 6.1
MEDIUM CVE-2024-4940 6.1
MEDIUM CVE-2023-6568 6.1
MEDIUM CVE-2023-27494 6.1
MEDIUM CVE-2024-37145 6.1
MEDIUM CVE-2024-36423 6.1
MEDIUM CVE-2024-36422 6.1
MEDIUM CVE-2024-8021 6.1
MEDIUM GHSA-564p-rx2q-4c8v 6.1
MEDIUM CVE-2025-49592 5.4
MEDIUM GHSA-364x-8g5j-x2pr 5.4
MEDIUM CVE-2025-58177 5.4
MEDIUM CVE-2026-25640 5.4
MEDIUM CVE-2026-40864 5.4
MEDIUM CVE-2026-44568 4.8
MEDIUM CVE-2026-28415 4.7
MEDIUM CVE-2026-33720 4.2
MEDIUM GHSA-w673-8fjw-457c 4.1
LOW CVE-2025-3777 3.5
LOW CVE-2025-59842
LOW CVE-2025-50736
MEDIUM CVE-2026-21883
MEDIUM CVE-2026-23528
CRITICAL CVE-2025-62593
MEDIUM CVE-2025-61669
UNKNOWN CVE-2026-42235
UNKNOWN CVE-2026-42230
HIGH CVE-2025-23205
MEDIUM CVE-2026-33709
HIGH CVE-2025-47783